Inclusion of Sensitive Information in Log Files in Salt - CVE-2021-25284

 

Inclusion of Sensitive Information in Log Files in Salt - CVE-2021-25284

Published: February 28, 2021


Vulnerability identifier: #VU50983
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25284
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to salt.modules.cmdmod stores sensitive information, such as passwords into the /var/log/salt/minion file. A local user can read the log files and gain access to sensitive data.


Affected software

Salt
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Manager Tools
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
Ubuntu
Fedora
SUSE Manager
salt (Debian package)
salt-common (Ubuntu package)
spacecmd
py26-compat-salt
salt-minion
salt-doc
salt
salt-common
salt-zsh-completion
salt-fish-completion
salt-bash-completion
salt-syndic
salt-standalone-formulas-configuration
salt-proxy
salt-ssh
salt-master
salt-cloud
salt-api
python3-salt
python2-salt
app-admin/salt

How to mitigate CVE-2021-25284

Install updates from vendor's website.

Salt - addressed in versions 3000.8, 3001.6, 3002.5
salt (Debian package) - addressed in versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1
salt-common (Ubuntu package) - update to Ubuntu Pro
spacecmd - addressed in versions 4.2.8-2.15.1, 4.2.8-2.18.1, 4.2.8-2.24.1
py26-compat-salt - addressed in versions 2016.11.10-6.8.1, 2016.11.10-10.22.1
salt-minion - addressed in versions 2016.11.10-43.69.1, 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.1
salt-doc - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-common - addressed in versions 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt-zsh-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-fish-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3002.2-8.41.1
salt-bash-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-syndic - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-standalone-formulas-configuration - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-proxy - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-ssh - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-master - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-cloud - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-api - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python3-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python2-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1
salt - addressed in versions 3001.6-1.fc32, 3002.5-1.fc33, 3002.5-1.fc34
app-admin/salt - update to 3004.2

External References

Related Security Bulletins